Intel

AIKIDO-2025-10709

jquery.validation is vulnerable to Inefficient Regular Expression Complexity

Inefficient Regular Expression Complexity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 14, 2025

75

High Risk

This Affects:

DOTNETjquery.validation
0.0.1 - 1.19.4
Fixed in 1.19.5
Are you affected? Scan for Free

TL;DR

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery.validation package, when an attacker is able to supply arbitrary input to the url2 method.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

jquery.validation is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.1 - 1.19.4.

How to fix this

Upgrade the jquery.validation library to the patch version.